Hi, Our Web Servers are placed in DMZ and when i try to update time synchronization then it shows me error. Seems something is getting blocked. Has NTP required to be add in the default inspection. Please suggest. Thanks.
I believe that there is not enough information here for us to really understand and provide answers about your issue. What device is providing the DMZ functionality (PIX, ASA, router, something else)? What access policies are in place for the DMZ? How are your web servers configured to get time? By default Windows servers run the Windows time service which implements a simplified version of NTP.
With normal access policies on a DMZ if the Windows server sends a request for time to some appropriate time source on the outside, since the request originated from inside the DMZ then responses should be allowed. If the time information is included in transmission originated from devices on the outside then you would need to configure access rules to permit this. If the request for time is sent from the server in the DMZ to some appropriate time source on the inside network then you would need to configure access rules to permit this traffic.
If you can clarify these aspects then perhaps we can provide better answers.
We are using ASA 5505. Application Servers are placed on DMZ and DB Servers are on Inside. The all App Server are mapped with Static Public IP and time is getting synchronized in App Server but not in DB Servers. We can access internet from DB and App Servers. Please Advice and let me know if you want anything else. Thanks
RADIUS and Symantec VIP.
I will use screenshots of ASDM, and at the end I will add the required CLI commands. the diagram below show a diagram of the steps the FW goes through when using 2FA authentication:
As you can see in Fig. 1&nbs...
Unable to get signature update from cisco.com
1. Make sure the router can get name resolution. Configure the router with a proper DNS name server.
ISR4451#utd threat-inspection signature update server cisco username xxxxx password yyyyy